CVE-2007-5849

CUPS <1.3.4 - RCE

Title source: llm

Description

Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.

Exploits (1)

exploitdb WORKING POC VERIFIED
by wei_wang · perldoslinux
https://www.exploit-db.com/exploits/30898

Scores

EPSS 0.3458
EPSS Percentile 97.0%

Details

CWE
CWE-189
Status published
Products (5)
easy_software_products/cups 1.2.4
easy_software_products/cups 1.2.9
easy_software_products/cups 1.2.10
easy_software_products/cups 1.2.12
easy_software_products/cups 1.3.3
Published Dec 19, 2007
Tracked Since Feb 18, 2026